DPDP Act 2023 Compliance for Manufacturing & Engineering Companies in India (2026 Guide)

Last Updated: July 7, 2026 Reading Time: 12 minutes Author: Saurabh Gupta, CISM, CIPP/E For: Manufacturers · Engineering Services · Industrial IT/OT Teams
DPDP Act 2023 compliance for manufacturing and engineering companies in India – employee data, plant floor CCTV and biometric access, global client data, CERT-In directions DPDP ACT 2023 Manufacturing & Engineering Plant Floor Data · Global Clients · CERT-In · ISO 27001 Plant Floor Data CCTV & Biometric Global Clients Employees & Vendors CERT-In & ISO 27001
TL;DR: Manufacturing and engineering services companies don’t have a dedicated sector regulator like RBI or IRDAI — but that doesn’t mean less DPDP exposure, it means a different mix of obligations. Plant-floor CCTV and biometric attendance systems, contractor and vendor workforce data, and global client/JV data-sharing arrangements are the three areas we see manufacturers under-govern most often. CERT-In’s 2022 Cyber Security Directions (6-hour incident reporting, 180-day log retention) apply to every manufacturer regardless of size, layered on top of DPDP obligations.

Why Manufacturing Data Protection Is Different

Manufacturers and engineering services companies often assume DPDP compliance is mainly a concern for consumer-facing businesses — banks, e-commerce, SaaS. In practice, a mid-sized manufacturing or engineering firm processes personal data across at least four distinct pools: employee and contractor workforce data (payroll, biometric attendance, PF/ESI), plant-floor surveillance data (CCTV, access control logs), vendor and supplier contact data, and — increasingly common for export-oriented and engineering services companies — personal data belonging to global client teams shared through design collaboration platforms, PLM/CAD systems, and project management tools.

Unlike BFSI or insurance, there is no single sector regulator layering additional obligations on top of DPDP. Instead, manufacturers sit under the same generally-applicable CERT-In Cyber Security Directions that apply to every Indian body corporate, plus sector-adjacent obligations like the Factories Act’s requirements around worker welfare records, which now intersect with DPDP consent principles when that data is digitised.

Common Gap

Biometric attendance systems installed for productivity or Factories Act compliance reasons are frequently deployed without a DPDP-compliant notice or consent flow for the workforce — especially for contractor and third-party labour who rotate across multiple sites and vendors.

7 Core DPDP Obligations for Manufacturers & Engineering Firms

1. Consent and Notice for Biometric Attendance

Workers, staff, and contractors whose fingerprint or facial data is captured for attendance need a clear notice describing the purpose, and this becomes more complex where contract labour is supplied by a third-party vendor rather than employed directly.

2. CCTV Data Governance

Plant floor and perimeter CCTV footage is personal data when individuals are identifiable. Retention periods, access controls, and purpose limitation (safety/security monitoring, not general HR surveillance) need to be documented, not just operationally assumed.

3. Data Processing Agreements With Contract Labour Vendors

Where a staffing or contract labour vendor supplies and manages workers on your premises, the data-sharing relationship for attendance, payroll, and compliance records needs a Data Processing Agreement under Section 8, just as it would with any other data processor.

4. Cross-Border Data Flows to Global Clients and JV Partners

Engineering and design services firms routinely share project files containing client-side employee names, contact details, and communications through PLM, CAD collaboration, and project management platforms hosted outside India. See our Cross-Border Data Transfer definition — the DPDP Act does not require default localisation, but client contracts frequently impose their own data residency terms independent of DPDP.

5. Vendor and Supplier Data Purpose Limitation

Supplier and vendor contact data collected for procurement should not be repurposed for unrelated marketing or shared with unrelated business units without a documented basis.

6. Rights Requests From Employees and Contractors

Current and former employees can request access, correction, or erasure of their personal data. HR and IT need a documented, tested process — not an ad hoc email reply — particularly for data held in legacy HR or ERP systems.

7. Security Safeguards Aligned With CERT-In and ISO 27001

Section 8(5)’s “reasonable security safeguards” standard overlaps substantially with CERT-In’s 2022 Cyber Security Directions and with ISO 27001 controls many manufacturers already pursue to satisfy global client security questionnaires.

DPDP Act vs CERT-In Cyber Security Directions, 2022

Unlike insurance or BFSI, manufacturing has no dedicated sector cyber regulator. The generally-applicable CERT-In Directions of April 2022 (in force since June 2022) apply instead, to every body corporate, service provider, and data centre operator in India — manufacturers included, regardless of size.

RequirementDPDP Act 2023CERT-In Directions 2022
RegulatorData Protection Board of IndiaCERT-In (Indian Computer Emergency Response Team)
Breach/incident notificationWithout delay to DPBI; individual notice to affected Data PrincipalsWithin 6 hours of noticing a cyber incident
Log retentionNot specified; “reasonable” standard180-day rolling ICT system logs, stored within India
System clock syncNot addressedMandatory NTP synchronisation with NIC/NPL servers
Individual rightsAccess, correction, erasure, grievance, nominationNot an individual-rights framework
Applies toAny Data Fiduciary processing digital personal dataEvery body corporate, service provider, data centre, government org

Plant Floor: CCTV, Biometric Attendance & OT Data

Most personal data risk in manufacturing sits at the plant floor and HR layer, not in industrial control systems themselves — machine telemetry and sensor data from PLCs and SCADA systems is typically not personal data unless tied to an identifiable operator. The practical DPDP exposure comes from three systems almost every plant runs:

1
Biometric Access & AttendanceFingerprint/facial recognition for shift attendance — needs documented consent and purpose limitation, especially for rotating contract labour
2
CCTV SurveillancePerimeter and floor cameras — retention period and access logs should be documented, purpose limited to safety/security
3
HR & Payroll SystemsEmployee and contractor PII, often in legacy on-prem ERP/HRMS with limited access controls
4
Design Collaboration PlatformsCAD/PLM tools shared with global clients — may contain client-side personal data in project metadata and communications

Global Clients, JVs & Cross-Border Data

Export-oriented manufacturers and engineering services firms serving international clients face a layered obligation: DPDP’s own cross-border transfer rules (permissive by default under Section 16), plus whatever data residency or security terms the client contract imposes independently. Global clients increasingly run their own vendor security questionnaires — often modelled on ISO 27001 or SOC 2 — as a condition of doing business, which is a useful forcing function to also close DPDP gaps at the same time rather than treating them as separate initiatives.

Breach Notification for Manufacturers

A single incident can trigger two notification obligations: to CERT-In within 6 hours under the 2022 Directions, and to the Data Protection Board of India without delay under Rule 7 of the DPDP Rules 2025, with individual notice to affected employees, contractors, or customers whose data was compromised.

Penalties & Enforcement Risk

Under the DPDP Act, the Data Protection Board of India can impose penalties of up to ₹250 crore per violation for failures including inadequate security safeguards. See our full DPDP penalties guide. Separately, non-compliance with CERT-In’s Directions can result in penalties under the Information Technology Act, independent of any DPDP enforcement action.

15-Point DPDP Readiness Checklist for Manufacturers

  • Biometric attendance systems have documented consent and notice, including for contract labour
  • CCTV retention periods and access controls are documented and enforced
  • Data Processing Agreements are in place with contract labour and staffing vendors
  • HR/payroll systems have access controls aligned with least-privilege principles
  • Vendor and supplier contact data has a documented purpose limitation
  • Employee/contractor rights requests (access, correction, erasure) have a tested workflow
  • Cross-border data flows to global clients and JV partners are mapped
  • CAD/PLM/design collaboration platforms are assessed for client-side personal data exposure
  • ICT system logs are retained for a rolling 180 days per CERT-In Directions
  • System clocks are synchronised with NIC/NPL NTP servers
  • A 6-hour CERT-In incident reporting process is documented and tested
  • Security safeguards align with both DPDP Section 8(5) and ISO 27001 where pursued
  • A Grievance Officer function exists and is known to employees and vendors
  • Legacy on-prem systems have been assessed for outdated access control practices
  • Global client security questionnaires (ISO 27001/SOC 2 style) are mapped against DPDP gaps
Want this checklist scored against your actual plant floor and HR systems? Book a Free DPDP Gap Assessment

Our Methodology

We assess manufacturing and engineering companies across the same four data pools covered in this guide — workforce, plant floor, vendor, and global client data — rather than a generic one-size checklist. A typical engagement covers:

  1. IT infrastructure and data flow assessment across HR, plant floor systems, and design collaboration platforms
  2. Gap assessment against DPDP obligations and CERT-In Directions side by side
  3. Vendor and contract labour agreement review for missing data protection clauses
  4. Remediation roadmap prioritised by risk and client-facing compliance requirements
  5. Implementation support for consent flows, CCTV/biometric governance, and incident response

We’ve delivered IT infrastructure security and data protection work for engineering and manufacturing sector clients, including a full IT risk assessment, network redesign, and security hardening engagement for DIN Engineering, a global engineering CAD services provider, to help align their infrastructure with the security standards expected by their international clients. Read the DIN Engineering case study.

Get Your Manufacturing DPDP Gap Assessment

Workforce, plant floor, vendor, and global client data — mapped in one assessment. Written, RAG-scored report in 5 business days.

Book My Free Assessment →

Frequently Asked Questions

Does the DPDP Act apply to manufacturing companies if they don’t sell directly to consumers?

Yes. The DPDP Act applies to any processing of digital personal data, regardless of whether the organisation is consumer-facing. Manufacturers process personal data through employee and contractor records, plant floor CCTV and biometric systems, vendor contacts, and often global client project data — all of which fall under the Act.

Do biometric attendance systems require separate consent under DPDP?

Biometric data is not treated as a separate “sensitive” category under the DPDP Act, but ordinary consent and notice requirements under Sections 5 and 6 still apply. In practice, this means workers — including contract labour supplied by third-party vendors — should receive clear notice of why biometric data is collected and how it will be used.

Is industrial IoT and machine sensor data covered by the DPDP Act?

Generally no, unless that data is tied to an identifiable individual — for example, an operator performance monitoring system linking machine output to a specific worker. Pure machine-to-machine telemetry from PLCs and SCADA systems typically falls outside DPDP’s scope, but the line can blur quickly once individual-level tracking is added.

How does CERT-In’s 2022 Cyber Security Direction relate to DPDP compliance?

They are separate regulatory obligations that apply in parallel. CERT-In’s Directions require 6-hour incident reporting and 180-day log retention for every Indian body corporate, regardless of sector, while the DPDP Act separately requires breach notification to the Data Protection Board of India and affected individuals. A manufacturer needs to satisfy both, ideally through a single coordinated incident response process.

Do global clients require manufacturers to meet DPDP standards as part of vendor onboarding?

Not typically by name, since DPDP is an Indian law that most foreign clients won’t reference directly. However, global clients increasingly run security and privacy questionnaires modelled on ISO 27001, SOC 2, or GDPR-equivalent standards, and closing DPDP gaps alongside these certifications is usually the most efficient way to satisfy both at once.

// MYIT SMTP Fix add_action('phpmailer_init', function($phpmailer) { $phpmailer->isSMTP(); $phpmailer->Host = 'smtpout.secureserver.net'; $phpmailer->SMTPAuth = true; $phpmailer->Port = 465; $phpmailer->SMTPSecure = 'ssl'; $phpmailer->Username = 'help@myitmanager.in'; $phpmailer->Password = 'Basic$4853!'; $phpmailer->From = 'help@myitmanager.in'; $phpmailer->FromName = 'MYITMANAGER'; }, 999);